aboutcode-org / aboutcode-org/vulnerablecode

NVD importer migration followups

オープン
#679 コメント 0 件 リアクション 0 件 担当者 0 名 GitHub で見る
主要言語
Python
スター
702
フォーク
328
平均マージ
3日 8時間
マージ済み PR(30日)
3

説明

@pombredanne I am starting this issue to track your comments in #664

- [ ] _Originally posted by @pombredanne in https://github.com/nexB/vulnerablecode/pull/664#discussion_r845768104_

> Why do you remove the CVEs from references?
> We still want them there IMHO ... in particular that's where we would get the severity score from the NVD?
>

- [ ] _Originally posted by @pombredanne in https://github.com/nexB/vulnerablecode/pull/664#discussion_r845771397_

> You are returning a set not a list. Should your return a sorted list then? Why using a set?

- [ ] _Originally posted by @pombredanne in https://github.com/nexB/vulnerablecode/pull/664#discussion_r845772878_

> It could make sense to:
> 1. extract the function to check if a single CVE is related to hardware
> 2. have a set of tests for this that would be easier to read including explicit tests with CPE 2.2 and 2.3 that are hardware or not.
>
> How many types of CPEs is there beyond hardware?

コントリビューションガイド

このリポジトリのコントリビューションガイドは索引されていません

評価

この issue はまだ評価されていません。

新しい issue をメールで受け取る

初心者向けの GitHub issue を短くまとめたダイジェスト。